---
title: Egress identities
description: Declare the addresses your outbound traffic leaves from, so a third party can allowlist you, and reach a Service without the public internet.
type: how-to
product: network
summary: The address set a partner allowlists, the promise when it cannot serve, and private links
updated: 2026-10-01
order: 1
---

<Callout tone="note" title="Today this runs on the management API">
The `egress_identities` and `private_links` commands below are in the CLI's command list, but api.sylphx.com does not serve them.
</Callout>

A partner that allowlists you needs one thing: the addresses your traffic
arrives from. An EgressIdentity declares them, one identity per region, so the
set is something you write down and hand over rather than something you
discover from the partner's logs.

## Declare an identity per region

`spec.region` is the whole spec: the region the addresses live in. Create one
identity for each region your project talks to a partner from, and give every
one of them to the partner.

```bash
sylphx network egress-identities create \
  --parent orgs/acme/projects/shop \
  --spec.region …
```

The addresses are not something you choose. Read the identity back and
`status.addresses` lists the IPv4 and IPv6 addresses traffic leaves from:

```bash
sylphx network egress-identities get orgs/acme/projects/shop/egress_identities/egress-identity
```

<Callout tone="note" title="Hand over the identity, not one address">
A partner that allowlists a single address from that list has allowlisted a
fraction of your traffic. Give them the addresses the identity reports, and
re-read them after a change: the identity is the stable thing, and the list is
what it currently reports.
</Callout>

## Traffic never leaves under an undeclared address

When the identity cannot serve, selected traffic is dropped. That is the point
of declaring it: no request of yours arrives at a partner from an address the
partner was not told about, so an allowlist on their side is a real boundary
rather than a hopeful one. A dropped request is a refusal you can see, not a
request that quietly came from somewhere else.

## Changing the set

`region` is the spec and the addresses follow from it, so an identity that names
another region reports that region's addresses. Read it back after the change
and hand the partner what it reports. Delete is `destructive`, so the CLI asks
before it runs, and the API takes an `etag` that must match the current one.

```bash
sylphx network egress-identities delete orgs/acme/projects/shop/egress_identities/egress-identity --yes
```

## Private links

A PrivateLink is the other direction: a customer network reaching a Service
without the public internet. Its spec names what is exposed and who may connect:

<PropertyTable
	properties={[
		{
			name: 'service',
			type: 'string',
			required: true,
			description: 'The Hosting Service exposed.',
		},
		{
			name: 'region',
			type: 'string',
			required: true,
			description: 'The region of the link.',
		},
		{
			name: 'allowed_consumers',
			type: 'string[]',
			required: true,
			description: 'The customer network accounts allowed to connect.',
		},
	]}
/>

```bash
sylphx network private-links create \
  --parent orgs/acme/projects/shop/envs/production \
  --spec.service … \
  --spec.region …
```

`status.state` is the lifecycle: `pending`, `established` or `rejected`. When it
is established, `status.endpoint_service` is the endpoint the consumer connects
its network to — that is what you send them. An established link keeps carrying
traffic while the control plane is impaired; only changes wait.

A link lives under an environment, so it is created, changed and deleted like
any other resource in one: `allowed_consumers` is the field you change as a
partner's accounts change, and Delete is `destructive`.

<RelatedDocs
	links={[
		{
			href: '/docs/api/egress_identities',
			label: 'The egress_identities collection',
			description: 'Every method, its scope and its examples.',
		},
		{
			href: '/docs/api/private_links',
			label: 'The private_links collection',
			description: 'Every method, its scope and its examples.',
		},
		{
			href: '/docs/platform/regions',
			label: 'Regions',
			description: 'The regions a project runs in, and what picking one means.',
		},
		{
			href: '/docs/network',
			label: 'Network',
			description: 'All five objects and what each one is for.',
		},
	]}
/>
